GPO Logging Using Gpsvc.log in Windows 7

Posted on January 10th, 2017 · Posted in Windows 7, Windows Server 2008 R2

The debug log Userenv.log  (%Systemroot%\Debug\UserMode\Userenv.log) could be used to thoroughly analyze the application of GPO in Windows XP and Windows Server 2003. Using this Group Policy logging, you could track the order and time of applying group policies, find the policies that slow down the booting and solve other GPO

Remote Desktop Connection Error: Outdated entry in the DNS cache

Posted on December 14th, 2016 · Posted in Windows Server 2008 R2
The connection cannot be completed because the remote computer that was reached is not the one you specified. This could be caused by an outdated entry in the DNS cache

Users have begun to complain that when trying to connect to the RDS (Remote Desktop Server) farm  running Windows Server 2008 R2 using the standard RD client (mstsc.exe) they often get an error:

How to Filter Event Logs by Username in Windows 2008 and higher

Posted on November 17th, 2016 · Posted in Windows Server 2008 R2, Windows Server 2012
filtered security log

In Windows Server 2003 or Windows XP, you could easily filter the events in the system Event Log Viewer by a specific user account if you enter the desired username in the User field of the log filter. But in Windows Server 2008 / Windows 7, this simple way of

Disable Creating Thumbs.db on Network Folders

Posted on November 14th, 2016 · Posted in Windows 7, Windows Server 2008 R2
Folder In Use The action can’t be completed because the folder or a file in it is open in another program

One of the subscribers has found an interesting peculiarity of Windows Explorer in Windows 7 when working with network shares. The problem was that right after copying or moving a directory in the share, the system refused to delete or rename it. You could only rename or delete this folder

Unable to Install Print Driver after KB3170455

Posted on October 7th, 2016 · Posted in Windows 10, Windows 7, Windows Server 2008 R2
A policy is in effect on your computer which prevents you from connecting to this print queue.

We have found an unpleasant problem with one of Microsoft security updates released in July. We mean KB3170455 released on July, 12, 2016. After the installation of this update, the problem of network printer connection may appear in the domain.

Fixing High Memory Usage by Metafile on Windows Server 2008 R2

Posted on July 25th, 2016 · Posted in Windows Server 2008 R2
metafile size in rammap utility

One of the file servers running Windows Server 2008 R2 encountered a problem of high RAM load resulting in the issues with the server and applications performance. It turned out that the memory was swamped by the system file cache containing file system metadata. The problem potentially affects all file

Windows Event Triggers

Posted on July 22nd, 2015 · Posted in Windows Server 2008 R2
Attach Task To Windows Event

In Windows Server 2008 (Vista) a new feature appeared that allowed to attach a Windows Scheduler task for any event in system logs. Using this feature, an administrator can assign a specific script or sending e-mail alerts to any Windows event. Let’s consider this feature in detail.

How to Monitor Active Sessions on IIS

Posted on May 29th, 2015 · Posted in Windows Server 2008 R2
Monitoring Active Users Sessions on IIS site

How to quickly estimate the current number of user sessions on the IIS website running on Windows Server? Such information will allow to determine and predict the load on the server, choose the best time for the maintenance and updates of the website.

How to Get Plain Text Passwords of Windows Users

Posted on June 18th, 2014 · Posted in Windows Server 2008 R2
mimikatz get plaintext username and passwords logged windows user

In this article, written as a part of a series devoted to Windows systems security (in the last article we discussed the security issues of passwords stored in the GPP), we will learn quite a simple method to get unencrypted passwords of all the users working in a Windows system.